← Back to the site

Legal

Privacy statement

What ATON BV does with personal data, and what you can ask us to do about it.

Last updated 22 August 2026.

Who is responsible

ATON BV is the controller for the personal data described here.

ATON BV
Willem de Zwijgerlaan 350, 1055 RD Amsterdam, Netherlands
Chamber of Commerce (KvK) 72184949
[email protected] · +31 6 15555560

What we collect, and why

DataWhere it comes fromWhy we have itLegal basis
Name, organisation, email address, country, subject of enquiry, and whatever you write in the message The enquiry form on this site, or an email, call or message you send us directly To answer your enquiry and, where it leads somewhere, to discuss and deliver a project Steps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries
Business contact details and correspondence You, or a colleague of yours, in the course of a project To perform the contract and keep a record of what was agreed Performance of a contract; legitimate interest in an accurate record
Technical log data — IP address, request time, page requested, user agent Automatically, by our hosting provider, when your browser requests a page To serve the site, and to keep it secure and available Legitimate interest in operating and securing the site

The enquiry form does not send data to us over the internet. By default it opens a message in your own email application with the details you entered, which you then choose to send. Nothing leaves your device unless you press send in your mail client.

What we do not do

Who else sees it

Only parties who need to, and only for the purposes above:

These parties act as processors on our instructions, under a data processing agreement, except where they are independent controllers in their own right (for example a customs authority).

Transfers outside the EEA

We work in Egypt, North Africa and the Gulf, and some of our providers are established outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission where one exists, and otherwise on the Commission's Standard Contractual Clauses together with any additional measures the transfer requires.

How long we keep it

Your rights

Under the General Data Protection Regulation you may ask us to:

Write to [email protected]. We answer within one month. We may ask you to confirm your identity first, so that we do not hand your data to somebody else.

Complaints

If you think we have handled your data badly, tell us and we will try to put it right. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live or work.

Security

This site is served over HTTPS. Access to our email and project records is restricted to the people who need it and protected by multi-factor authentication. No system is perfect; if we suffer a breach that presents a risk to you, we will notify you and the supervisory authority as the GDPR requires.

Changes

If we change how we handle personal data — for example by adding a server-side contact form or an analytics tool — we will update this statement and change the date at the top before the change takes effect.